For community to? : PrimeFaces 6.1.1 Released with Important Security Updates

UI Components for JSF
Post Reply
kukeltje
Expert Member
Posts: 9605
Joined: 17 Jun 2010, 13:34
Location: Netherlands

20 May 2017, 09:49

I read this article: PrimeFaces 6.1.1 Released with Important Security Updates

Where it states:
Security Update

We are unable to go into the details however an important fix for security has been included so if you are on 6.1 we strongly suggest updating to 6.1.1 and for users on 6.0, 6.0.19 is the suggested version.
So if it is that important, 6.1 is totally useless by users of the community version. If upgrading to a 6.1.1 elite version is the only option (besides using an 'unstable' trunk version), PrimeFaces is giving off a very bad signal. I think this would really justify a 6.1-SR (security release) or 6.2 release OR make 6.1.1available to or some different solution.

https://github.com/primefaces/primefaces/issues/2375

Jorge
Posts: 25
Joined: 21 Sep 2011, 14:00

20 May 2017, 18:59

I received the email with the security update and immediately went to the Primefaces repository to see if it was made available to Us so we can change our projects (maven pom) and it wasn't.

The only place I found it was in the download section of the site and it is for elite members only.
So I totally agree with @Ronald here. Also the version 6.0.19 ins't available at the download section.

If this security update is so important you really should do what @Ronald said "I think this would really justify a 6.1-SR (security release)"

I've even bought one of the templates from Primefaces, but due to a bug (in SelectManyCheckbox) on the version 6.1 (and previous versions) I moved to the version 6.1.RC3 (available in the Primefaces Repository).

Now it is useless. The bug persists in versions prior to 6.1 so I had to use the version 6.1.RC3 which was corrected.

So what to do now??
Jorge Campos
--
Eclipse Juno
Primefaces 6.1.RC3
JSF 2.2.8
Apache Tomcat 8.5.14

mert.sincan
Posts: 5281
Joined: 29 Jun 2013, 12:38

20 May 2017, 21:03

Hi @Jorge,
I've even bought one of the templates from Primefaces, but due to a bug (in SelectManyCheckbox) on the version 6.1 (and previous versions) I moved to the version 6.1.RC3 (available in the Primefaces Repository).
- I think you can create a forum issue for your layout and theme issue under "Premium Layouts and Themes" section on the forum. viewforum.php?f=22
Also, I didn't see a difference about SelectManyCheckbox between 6.1 and 6.1.RC3 https://github.com/primefaces/primeface ... s%3Aclosed

diego_99
Posts: 5
Joined: 15 May 2017, 10:06

22 May 2017, 11:55

I think the same as @kukeltje.

I see a post that someone try to build 6.1.1 from source from GitHub...

TracePF
Posts: 3
Joined: 05 Feb 2016, 19:38

23 May 2017, 09:46

Yes, so far getting very little advice (i.e. none). It's disappointing for something that has been labelled as an important security update.
--
PrimeFaces 6.0, Mojarra 2.2.8-17 on WebLogic 12.2.1.2.0

User avatar
ericbent
Posts: 2
Joined: 23 May 2017, 15:02

23 May 2017, 16:57

So what's the principal difference? I did not get. Can somebody explain briefly, please?

Post Reply

Return to “PrimeFaces”

  • Information
  • Who is online

    Users browsing this forum: Google [Bot] and 57 guests